TT Lab
Get started
Learn Learning paths Courses

LFCS — Linux Foundation System Administrator

Permission Bits, umask and the ACL Mask

Continue in TT Lab

Goal

You set up octal and symbolic modes, umask, special bits, and ACLs with masks in turn inside one directory, and see their interaction with your own eyes.

Why it matters

A permission problem starts with "why doesn't it work" and usually ends with chmod 777. The reason that habit gets caught in an audit is simple — what was needed was an exception for one person, but the door was opened to everyone. The judgment to use an ACL instead of creating a new group when a requirement arises that the three slots (owner, group, other) cannot express, and the judgment to unify the group with setgid when several people pile files into the same directory, are the core of this domain. The mask is especially important. Even after you grant an ACL exactly, if someone later runs chmod once, the mask is recalculated and that ACL is silently disabled. You have to be able to read the #effective: marker of getfacl to recognize this situation in 5 seconds.

Steps

  1. Create the directory /root/lfcs-perm/, and create a group lfcsteam and users lfcsone and lfcstwo. Both users must have lfcsteam as a supplementary group (the primary group is each one's own private group).
  2. Create /root/lfcs-perm/notes.txt and set its permissions to 640 and its group to lfcsteam.
  3. Put any content in /root/lfcs-perm/run.sh, and use symbolic mode to set its permissions to 750 and its group to lfcsteam.
  4. In a shell where umask is changed to 0027, newly create the file /root/lfcs-perm/umask-demo/newfile and the directory /root/lfcs-perm/umask-demo/newdir. Then write three lines in /root/lfcs-perm/umask.txt: umask=0027, file=<새 파일의 권한>, and dir=<새 디렉터리의 권한> (file= followed by the new file's permissions, and dir= followed by the new directory's permissions).
  5. Create /root/lfcs-perm/probe owned by root with permissions 4755, and create the directory /root/lfcs-perm/tools/ with 1777.
  6. Create /root/lfcs-perm/shared/ with group lfcsteam and permissions 2770, and then create handoff.txt inside it. The file's group must become lfcsteam by inheritance.
  7. Give handoff.txt an ACL of rw- for lfcsone and r-- for lfcstwo, and give the shared/ directory a default ACL of rwx for the lfcsteam group.
  8. Lower the ACL mask of handoff.txt to r--, and write one line in /root/lfcs-perm/mask.txt: lfcsone_effective=<마스크 적용 후 lfcsone 의 실효 권한> (lfcsone_effective= followed by lfcsone's effective permissions after the mask is applied).

Notes

Prepare groups and users for collaboration

Create the directory /root/lfcs-perm/, and create a group lfcsteam and users lfcsone and lfcstwo. Both users must have lfcsteam as a supplementary group (the primary group is each one's own private group).

Both users must have the team group as a supplementary group. If you make the team group their primary group as well, the inheritance experiment in the later steps loses its meaning.

Octal mode and group ownership

Create /root/lfcs-perm/notes.txt and set its permissions to 640 and its group to lfcsteam.

Permissions and group are different commands. 640 means read and write for the owner, read for the group, and nothing for others.

Setting permissions with symbolic mode

Put any content in /root/lfcs-perm/run.sh, and use symbolic mode to set its permissions to 750 and its group to lfcsteam.

Symbolic mode combines a target (u/g/o/a), an operator (+/-/=), and permissions (r/w/x). The equals sign erases the rest and leaves only the specified value.

How umask trims the default permissions

In a shell where umask is changed to 0027, newly create the file /root/lfcs-perm/umask-demo/newfile and the directory /root/lfcs-perm/umask-demo/newdir. Then write three lines in /root/lfcs-perm/umask.txt: umask=0027, file=<새 파일의 권한>, and dir=<새 디렉터리의 권한> (file= followed by the new file's permissions, and dir= followed by the new directory's permissions).

The base value for files is 666 and for directories is 777, and the umask bits are subtracted from there. Do not fix it with chmod afterward; create them fresh in the shell where you changed umask.

The setuid and sticky bits

Create /root/lfcs-perm/probe owned by root with permissions 4755, and create the directory /root/lfcs-perm/tools/ with 1777.

A special bit is the leading digit of four octal digits. setuid is 4, setgid is 2, and sticky is 1. For setuid, who the owner is is the key.

A setgid collaboration directory

Create /root/lfcs-perm/shared/ with group lfcsteam and permissions 2770, and then create handoff.txt inside it. The file's group must become lfcsteam by inheritance.

Order matters. Inheritance happens only if you set the bit on the directory and match the group first, and then create the file inside.

Named-user ACL and default ACL

Give handoff.txt an ACL of rw- for lfcsone and r-- for lfcstwo, and give the shared/ directory a default ACL of rwx for the lfcsteam group.

On the file you put individual user entries, and on the directory you put an entry to pass on to files created from now on. The latter needs a separate flag.

The mask trims the effective permissions

Lower the ACL mask of handoff.txt to r--, and write one line in /root/lfcs-perm/mask.txt: lfcsone_effective=<마스크 적용 후 lfcsone 의 실효 권한> (lfcsone_effective= followed by lfcsone's effective permissions after the mask is applied).

The mask is the upper limit for all entries except the owner and other. There is an entry notation that specifies the mask by itself, and once you lower it, getfacl shows the effective permissions alongside.